Prevent requestOptions.headers from being published to the client (in case it contains Authentication info)

This commit is contained in:
Erik Ziegler committed 2017-04-12 12:04:46 +02:00
1 parent cba6c6201c
commit bf97c3ebe2
1 file changed
+7 -1
@@ -3,6 +3,12 @@ import { OHIF } from 'meteor/ohif:core';
Meteor.publish('studyImportStatus', () => OHIF.studylist.collections.StudyImportStatus.find());
Meteor.publish('servers', () => Servers.find());
// When publishing Servers Collection, do not publish the requestOptions.headers
// field in case any authentication information is being passed
Meteor.publish('servers', () => Servers.find({}, {
fields: {
'requestOptions.headers': 0
}
}));
Meteor.publish('currentServer', () => CurrentServer.find());